★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/server_security_article-4067.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Server Security 11/26/2001 13:21

Vulnerability Life Cycles

NWC
Posted By: Jen Olson
11/26/2001

The vulnerability life cycle has three phases: the research/discovery phase -- in which both malicious and nonmalicious security researchers seek new holes in products; the disclosure phase -- in which the discoverer of the new vulnerability tells others about it; and the exploitation phase -- in which the specifics of bug information are incorporated into a program designed to take advantage of the vulnerability.

Trace Unix exploit code in the late 1980s and early 1990s and you'll find that vulnerability information and exploit code commonly circulated in the underground long before they made their way to FIRST, CERT or Bugtraq circles. Attackers used this knowledge as trump cards: Even if your Unix machine patches were up to date, you obviously had no patch for unknown holes. These vulnerabilities still exist today, leaving many systems in a "pants-down" state. This phenomena is one of the primary reasons defense-in-depth strategies are so important. We're not battling just the known; we're battling the unknown too.


Click here to go to this article.

Key steps to bolster security
Nov 29

Oops! Linux Bug Escapes Early
Nov 29

Judge Dismisses Felten Encryption Lawsuit Against RIAA
Nov 29

Court upholds ban on DVD-cracking code
Nov 29

Common sense key to beating hackers
Nov 28

Linux servers at risk from 'serious' flaw
Nov 28

PKCS #11 openCryptoki for Linux
Nov 28

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000